Threat Brief: March 2026 Escalation of Cyber Risk Related to Iran (Updated March 26)
2026-03-27T08:51:39Z•65746f45a7625f04a59dd17269d986c01d65f6357e5aa5797af4394369eb02e6
ai-agentsai-in-malwareboggy-serpensespionagehandala-hackidentity-weaponizationiranian-threat-actorsllm-guardrail-bypassloadersmicrosoft-intune-abusephishingprompt-injectionratrecruitment-fraudsoutheast-asiathreat-actor-clusteringusbfectwiper-attacks
What happened
Unit 42 (March 2026) published multiple interrelated threat reports describing an uptick in Iranian-aligned destructive and espionage activity, expanding use of AI in malware, and growing abuse of social engineering and legitimate management tooling. Notable observations include increased wiper deployments by Handala Hack (aka Void Manticore) leveraging phishing and Microsoft Intune misuse; Boggy Serpens’ evolution to AI-enhanced malware and refined social engineering; identity weaponization and broader Iranian cyber operations; targeted espionage campaigns in Southeast Asia using USBFect, RAT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- paloalto_unit42
- Record identifier
- 65746f45a7625f04a59dd17269d986c01d65f6357e5aa5797af4394369eb02e6
- Enrichment time
- 2026-03-27T08:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.